PhishLabs IOC EIR

Get Email Incident Reports from PhishLabs.

Data Enrichment & Threat Intelligence · PhishLabs

Details

IDPhishLabs IOC EIR
ProviderFortra
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

This integration was integrated and tested with V1.0 of PhishLabs IOC EIR api

Use Cases

  • Get live EIR from PhishLabs
  • Get EIR by filters from PhishLabs

Detailed Description

Phishlabs Email Incident Response (EIR) is a solution that protects against threats that make it past your email security stack and into your employee inboxes. With Email Incident Response, enterprises can detect, prevent, and respond to these threats.

  • Suspicious Email Analysis
  • Email Threat Intelligence

Configure PhishLabs IOC EIR on Cortex XSOAR

  1. Navigate to Settings > Integrations  Servers & Services.
  2. Search for PhishLabs IOC EIR.
  3. Click Add instance to create and configure a new integration instance.
    • Name: a textual name for the integration instance.
    • Server URL (e.g. https://example.net)
    • User
    • Source Reliability. Reliability of the source providing the intelligence data. (The default value is B - Usually reliable)
    • Fetch incidents
    • First fetch timestamp ( e.g., 12 hours, 7 days)
    • Fetch limit
    • Trust any certificate (not secure)
    • Use system proxy settings
  4. Click Test to validate the new instance.

Fetch Incidents

Fetch incidents done by the following configuration:

  • Fetch limit - limit amount of incidents by fetch
  • First fetch timestamp - date for starting collecting incidents (1 days ago, 1 hours ago etc)
  • Incident type
[
  {
    "name": "PhishLabs IOC - EIR: INC0528925",
    "occurred": "2019-10-15T16:31:09Z",
    "rawJSON": {
            "id": "INC0528925",
            "service": "EIR",
            "title": "Deploymentliste release 10.0 in PROD am 15.10.2019",
            "description": "",
            "status": "Closed",
            "details": {
                "caseType": "Response",
                "classification": "No Threat Detected",
                "subClassification": "No Threat Detected",
                "severity": null,
                "emailReportedBy": "johnnydepp@gmail.com",
                "submissionMethod": "Attachment",
                "sender": "johnnydepp@gmail.com",
                "emailBody": "Test",
                "urls": [
                    {
                        "url": "google.com",
                        "malicious": false,
                        "maliciousDomain": false
                    }
                ],
                "attachments": [],
                "furtherReviewReason": null,
                "offlineUponReview": false
            },
            "created": "2019-10-15T16:31:08Z",
            "modified": "2019-10-15T16:31:09Z",
            "closed": "2019-10-15T16:31:09Z",
            "duration": 0
        }
  }
]

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

  1. phishlabs-ioc-eir-get-incidents
  2. phishlabs-ioc-eir-get-incident-by-id

1. phishlabs-ioc-eir-get-incidents


Get EIR incidents from PhishLabs-IOC EIR service (dafault limit 25 incidents)

Base Command

phishlabs-ioc-eir-get-incidents

Input
Argument Name Description Required
status Filter incidents that are opened or closed. Optional
created_after Return Incidents created on or after the given timestamp Timestamp is in RFC3339 format(2019-04-12T23:20:50Z) Optional
created_before Return Incidents created on or before the given timestamp Timestamp is in RFC3339 format(2019-04-12T23:20:50Z) Optional
closed_after Return Incidents closed on or after the given timestamp Timestamp is in RFC3339 format(2019-04-12T23:20:50Z) Optional
closed_before Return Incidents closed on or before the given timestamp Timestamp is in RFC3339 format(2019-04-12T23:20:50Z) Optional
sort Return Incidents sorted by the given column. Optional
direction Return Incidents sorted by the given order. This will be applied to the given sort parameter. Optional
limit Limit amounts of incidents (0-50, default 25) Optional
offset Offset from last incident Optional
period Period to query on 1 days, 2 hours Optional

 

Context Output
Path Type Description
PhishLabsIOC.EIR.CaseType String Incident reason type
PhishLabsIOC.EIR.Classification String Incident classification
PhishLabsIOC.EIR.SubClassification String Detailed classification
PhishLabsIOC.EIR.Severity String Incident severity
PhishLabsIOC.EIR.SubmissionMethod String Email submission method
PhishLabsIOC.EIR.FurtherReviewReason String Incident further review reason
PhishLabsIOC.EIR.ID String Id of incident
PhishLabsIOC.EIR.Title String Title of reported incident
PhishLabsIOC.EIR.Description String Description of reporeted incident
PhishLabsIOC.EIR.Status Boolean Status of reported incident
PhishLabsIOC.EIR.Created Date Date of incident creation
PhishLabsIOC.EIR.Modified Date Date of incident last modified
PhishLabsIOC.EIR.Closed Date Date of incident closing
PhishLabsIOC.EIR.Duration Number Duration until closing incident in seconds
PhishLabsIOC.EIR.EmailReportedBy String User who reported the incident
PhishLabsIOC.EIR.Email.EmailBody String Email body
PhishLabsIOC.EIR.Email.Sender String Email sender
PhishLabsIOC.EIR.Email.URL.URL String Url found in body
PhishLabsIOC.EIR.Email.URL.Malicious Boolean Is the url malicious?
PhishLabsIOC.EIR.Email.URL.MaliciousDomain Boolean Is the url domain malicious?
PhishLabsIOC.EIR.Email.Attachment.FileName String Name of the attached file
PhishLabsIOC.EIR.Email.Attachment.MimeType String Attachemt mime type
PhishLabsIOC.EIR.Email.Attachment.MD5 String Attachemt md5 hash
PhishLabsIOC.EIR.Email.Attachment.SHA256 String Attachemt sha256 hash
PhishLabsIOC.EIR.Email.Attachment.Malicious Boolean Is the file malicious?
Email.To String The recipient of the email.
Email.From String The sender of the email.
Email.Body/HTML String The plain-text version of the email.
File.Name String The full file name (including file extension).
File.SHA256 Unknown The SHA256 hash of the file.
File.MD5 String The MD5 hash of the file.
File.Malicious.Vendor String The vendor that reported the file as malicious.
File.Malicious.Description String A description explaining why the file was determined to be malicious.
URL.Data String The URL
URL.Malicious.Vendor String The vendor reporting the URL as malicious.
URL.Malicious.Description String A description of the malicious URL.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score String The actual score.

 

Command Example

!phishlabs-ioc-eir-get-incidents limit=3

Context Example
{
    "DBotScore": [
        {
            "Indicator": "https://google.com",
            "Score": 1,
            "Type": "URL",
            "Vendor": "PhishLabs IOC - EIR"
        }
    ],
    "Email": [
        {
            "Body/HTML": "Example body",
            "From": "LinkedIn Sales Navigator  not@domain.com",
            "To": "Michael Mammele not@domain.com"
        },
        {
            "Body/HTML": "Example body",
            "From": "Tony Prince not@domain.com",
            "To": "Tony Prince not@domain.com"
        },
        {
            "Body/HTML": "Example body",
            "From": "FileDoc2 not@domain.com",
            "To": "John LaCour not@domain.com"
        }
    ],
    "File": [],
    "PhishLabsIOC": {
        "EIR": [
            {
                "CaseType": "Link",
                "Classification": "No Threat Detected",
                "Closed": "2019-11-05T23:23:06Z",
                "Created": "2019-11-05T22:05:52Z",
                "Description": "",
                "Duration": 4635,
                "Email": {
                    "Attachment": [],
                    "EmailBody": "Example body",
                    "Sender": "LinkedIn Sales Navigator  not@domain.com",
                    "URL": [
                        {
                            "Malicious": false,
                            "MaliciousDomain": false,
                            "URL": "https://google.com"
                        }
                    ]
                },
                "EmailReportedBy": "Michael Mammele not@domain.com",
                "FurtherReviewReason": null,
                "ID": "INC0682881",
                "Modified": "2019-11-05T23:23:06Z",
                "Severity": null,
                "Status": "Closed",
                "SubClassification": "No Threat Detected",
                "SubmissionMethod": "Attachment",
                "Title": "See who else can influence your deals"
            }
    ]
}
Human Readable Output

PhishLabs IOC - EIR - incidents

ID Title Status Created Classification SubClassification EmailReportedBy
INC0682881 See who else can influence your deals Closed 2019-11-05T22:05:52Z No Threat Detected No Threat Detected Michael Mammele not@domain.com
INC0682040 FW: Tuesday, November 5, 2019 Closed 2019-11-05T20:30:48Z Malicious Link - Phishing Tony Prince not@domain.com
INC0681982 Tuesday, November 5, 2019 Closed 2019-11-05T20:25:22Z Malicious Link - Phishing John LaCour not@domain.com

2. phishlabs-ioc-eir-get-incident-by-id


Returns a single Incident based on the given ID.

Base Command

phishlabs-ioc-eir-get-incident-by-id

Input
Argument Name Description Required
incident_id ID of Incident, Get it from previous command Required

 

Context Output
Path Type Description
PhishLabsIOC.EIR.CaseType String Incident reason type
PhishLabsIOC.EIR.Classification String Incident classification
PhishLabsIOC.EIR.SubClassification String Detailed classification
PhishLabsIOC.EIR.Severity String Incident severity
PhishLabsIOC.EIR.SubmissionMethod String Email submission method
PhishLabsIOC.EIR.FurtherReviewReason String Incident further review reason
PhishLabsIOC.EIR.ID String Id of incident
PhishLabsIOC.EIR.Title String Title of reported incident
PhishLabsIOC.EIR.Description String Description of reporeted incident
PhishLabsIOC.EIR.Status Boolean Status of reported incident
PhishLabsIOC.EIR.Created Date Date of incident creation
PhishLabsIOC.EIR.Modified Date Date of incident last modified
PhishLabsIOC.EIR.Closed Date Date of incident closing
PhishLabsIOC.EIR.Duration Number Duration until closing incident in seconds
PhishLabsIOC.EIR.EmailReportedBy String User who reported the incident
PhishLabsIOC.EIR.Email.EmailBody String Email body
PhishLabsIOC.EIR.Email.Sender String Email sender
PhishLabsIOC.EIR.Email.URL.URL String Url found in body
PhishLabsIOC.EIR.Email.URL.Malicious Boolean Is the url malicious?
PhishLabsIOC.EIR.Email.URL.MaliciousDomain Boolean Is the url domain malicious?
PhishLabsIOC.EIR.Email.Attachment.FileName String Name of the attached file
PhishLabsIOC.EIR.Email.Attachment.MimeType String Attachemt mime type
PhishLabsIOC.EIR.Email.Attachment.MD5 String Attachemt md5 hash
PhishLabsIOC.EIR.Email.Attachment.SHA256 String Attachemt sha256 hash
PhishLabsIOC.EIR.Email.Attachment.Malicious Boolean Is the file malicious?
Email.To String The recipient of the email.
Email.From String The sender of the email.
Email.Body/HTML String The plain-text version of the email.
File.Name String The full file name (including file extension).
File.SHA256 Unknown The SHA256 hash of the file.
File.MD5 String The MD5 hash of the file.
File.Malicious.Vendor String The vendor that reported the file as malicious.
File.Malicious.Description String A description explaining why the file was determined to be malicious.
URL.Data String The URL
URL.Malicious.Vendor String The vendor reporting the URL as malicious.
URL.Malicious.Description String A description of the malicious URL.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score String The actual score.
Command Example

!phishlabs-ioc-eir-get-incident-by-id incident_id=INC0671150

Context Example
{
    "DBotScore": [
        {
            "Indicator": "https://google.com",
            "Score": 1,
            "Type": "URL",
            "Vendor": "PhishLabs IOC - EIR"
        }
    ],
    "Email": [
        {
            "Body/HTML": "Example body",
            "From": "LinkedIn Sales Navigator  not@domain.com",
            "To": "Michael Mammele not@domain.com"
        }
    ],
    "File": [],
    "PhishLabsIOC": {
        "EIR": [
            {
                "CaseType": "Link",
                "Classification": "No Threat Detected",
                "Closed": "2019-11-05T23:23:06Z",
                "Created": "2019-11-05T22:05:52Z",
                "Description": "",
                "Duration": 4635,
                "Email": {
                    "Attachment": [],
                    "EmailBody": "Example body",
                    "Sender": "LinkedIn Sales Navigator  not@domain.com",
                    "URL": [
                        {
                            "Malicious": false,
                            "MaliciousDomain": false,
                            "URL": "https://google.com"
                        }
                    ]
                },
                "EmailReportedBy": "Michael Mammele not@domain.com",
                "FurtherReviewReason": null,
                "ID": "INC0682881",
                "Modified": "2019-11-05T23:23:06Z",
                "Severity": null,
                "Status": "Closed",
                "SubClassification": "No Threat Detected",
                "SubmissionMethod": "Attachment",
                "Title": "See who else can influence your deals"
            }
    ]
}

Configuration parameters

  • url — Server URL (e.g. https://example.net) (required)
  • credentials — User (required)
  • integrationReliability — Source Reliability (required)
  • isFetch — Fetch incidents
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • fetchTime — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  • fetchLimit — Fetch limit
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (2)

  • phishlabs-ioc-eir-get-incident-by-id

    Returns a single Incident based on the given ID.

  • phishlabs-ioc-eir-get-incidents

    Returns EIR incidents from PhishLabs-IOC EIR service. The default number of incidents returned is 25.

category: Data Enrichment & Threat Intelligence
provider: Fortra
commonfields:
  id: PhishLabs IOC EIR
  version: -1
sectionorder:
- Connect
- Collect
configuration:
- defaultvalue: https://caseapi.phishlabs.com
  display: Server URL (e.g. https://example.net)
  name: url
  required: true
  type: 0
  section: Connect
- display: User
  name: credentials
  required: true
  type: 9
  section: Connect
- display: Source Reliability
  name: integrationReliability
  type: 15
  required: true
  additionalinfo: Reliability of the source providing the intelligence data.
  defaultvalue: B - Usually reliable
  options:
  - A+ - 3rd party enrichment
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  section: Collect
- display: Fetch incidents
  name: isFetch
  type: 8
  required: false
  section: Collect
- display: Incident type
  name: incidentType
  type: 13
  required: false
  section: Collect
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  section: Collect
  advanced: true
- defaultvalue: '1 hours'
  section: Collect
  display: First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  name: fetchTime
  type: 0
  required: false
- display: Fetch limit
  name: fetchLimit
  section: Collect
  type: 0
  required: false
  defaultvalue: '25'
- display: Trust any certificate (not secure)
  name: insecure
  section: Connect
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  section: Connect
  required: false
description: Get Email Incident Reports from PhishLabs.
display: PhishLabs IOC EIR
name: PhishLabs IOC EIR
script:
  commands:
  - arguments:
    - auto: PREDEFINED
      description: Filter incidents by status. Can be "open" or "closed".
      name: status
      predefined:
      - open
      - closed
    - description: |-
        Return incidents created on or after this timestamp.
        The timestamp is in RFC3339 format (2019-04-12T23:20:50Z).
      name: created_after
    - description: |-
        Return Incidents created on or before this timestamp.
        The timestamp is in RFC3339 format (2019-04-12T23:20:50Z).
      name: created_before
    - description: |-
        Return Incidents closed on or after this timestamp.
        The timestamp is in RFC3339 format (2019-04-12T23:20:50Z).
      name: closed_after
    - description: |-
        Returns Incidents closed on or before the given timestamp
        Timestamp is in RFC3339 format(2019-04-12T23:20:50Z).
      name: closed_before
    - auto: PREDEFINED
      description: Returns incidents sorted by a column. Can be "created_at" or "closed_at".
      name: sort
      predefined:
      - created_at
      - closed_at
    - auto: PREDEFINED
      description: How to sort returned incidents. This will be applied to the given sort parameter. Can be "asc" (ascending) or "desc" (descending).
      name: direction
      predefined:
      - asc
      - desc
    - defaultValue: '25'
      description: The maximum number of incidents to return (0-50). Default is 25.
      name: limit
    - defaultValue: '0'
      description: Offset from last incident.
      name: offset
    - description: The time range for which to return incidents (<number> <time unit>, e.g., 12 hours, 7 days).
      name: period
    description: Returns EIR incidents from PhishLabs-IOC EIR service. The default number of incidents returned is 25.
    name: phishlabs-ioc-eir-get-incidents
    outputs:
    - contextPath: PhishLabsIOC.EIR.CaseType
      description: Incident reason type.
      type: String
    - contextPath: PhishLabsIOC.EIR.Classification
      description: Incident classification.
      type: String
    - contextPath: PhishLabsIOC.EIR.SubClassification
      description: Detailed classification.
      type: String
    - contextPath: PhishLabsIOC.EIR.Severity
      description: Incident severity.
      type: String
    - contextPath: PhishLabsIOC.EIR.SubmissionMethod
      description: Email submission method.
      type: String
    - contextPath: PhishLabsIOC.EIR.FurtherReviewReason
      description: Incident further review reason.
      type: String
    - contextPath: PhishLabsIOC.EIR.ID
      description: ID of the incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Title
      description: Title of the reported incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Description
      description: Description of the reported incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Status
      description: Status of the reported incident.
      type: Boolean
    - contextPath: PhishLabsIOC.EIR.Created
      description: Date that the incident was created.
      type: Date
    - contextPath: PhishLabsIOC.EIR.Modified
      description: Date that the incident was last modified.
      type: Date
    - contextPath: PhishLabsIOC.EIR.Closed
      description: Date that the incident was closed.
      type: Date
    - contextPath: PhishLabsIOC.EIR.Duration
      description: Time until the incident will be closed (in seconds).
      type: Number
    - contextPath: PhishLabsIOC.EIR.EmailReportedBy
      description: User who reported the incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.EmailBody
      description: Email body.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Sender
      description: Email sender.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.URL.URL
      description: URL found in the email body.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.URL.Malicious
      description: Whether the URL is malicious.
      type: Boolean
    - contextPath: PhishLabsIOC.EIR.Email.URL.MaliciousDomain
      description: Whether the URL domain is malicious.
      type: Boolean
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.FileName
      description: Name of the attached file.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.MimeType
      description: Attachment MIME type.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.MD5
      description: MD5 hash of the attachment.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.SHA256
      description: SHA256 hash of the attachment.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.Malicious
      description: Whether the file is malicious.
      type: Boolean
    - contextPath: Email.To
      description: The recipient of the email.
      type: String
    - contextPath: Email.From
      description: The sender of the email.
      type: String
    - contextPath: Email.Body/HTML
      description: The plain-text version of the email.
      type: String
    - contextPath: File.Name
      description: The full file name (including file extension).
      type: String
    - contextPath: File.SHA256
      description: The SHA256 hash of the file.
      type: Unknown
    - contextPath: File.MD5
      description: The MD5 hash of the file.
      type: String
    - contextPath: File.Malicious.Vendor
      description: The vendor that reported the file as malicious.
      type: String
    - contextPath: File.Malicious.Description
      description: A description explaining why the file was determined to be malicious.
      type: String
    - contextPath: URL.Data
      description: The URL.
      type: String
    - contextPath: URL.Malicious.Vendor
      description: The vendor reporting the URL as malicious.
      type: String
    - contextPath: URL.Malicious.Description
      description: A description of the malicious URL.
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: String
  - arguments:
    - description: The ID of the incident.
      name: incident_id
      required: true
    description: Returns a single Incident based on the given ID.
    name: phishlabs-ioc-eir-get-incident-by-id
    outputs:
    - contextPath: PhishLabsIOC.EIR.CaseType
      description: Incident reason type.
      type: String
    - contextPath: PhishLabsIOC.EIR.Classification
      description: Incident classification.
      type: String
    - contextPath: PhishLabsIOC.EIR.SubClassification
      description: Detailed classification..
      type: String
    - contextPath: PhishLabsIOC.EIR.Severity
      description: Incident severity.
      type: String
    - contextPath: PhishLabsIOC.EIR.SubmissionMethod
      description: Email submission method.
      type: String
    - contextPath: PhishLabsIOC.EIR.FurtherReviewReason
      description: Incident further review reason.
      type: String
    - contextPath: PhishLabsIOC.EIR.ID
      description: ID of the incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Title
      description: Title of the reported incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Description
      description: Description of the reported incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Status
      description: Status of the reported incident.
      type: Boolean
    - contextPath: PhishLabsIOC.EIR.Created
      description: Date that the incident was created.
      type: Date
    - contextPath: PhishLabsIOC.EIR.Modified
      description: Date that the incident was last modified.
      type: Date
    - contextPath: PhishLabsIOC.EIR.Closed
      description: Date that the incident was closed.
      type: Date
    - contextPath: PhishLabsIOC.EIR.Duration
      description: Time until the incident will be closed (in seconds).
      type: Number
    - contextPath: PhishLabsIOC.EIR.EmailReportedBy
      description: User who reported the incident.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.EmailBody
      description: Email body.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Sender
      description: Email sender.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.URL.URL
      description: URL found in the email body.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.URL.Malicious
      description: Whether the URL is malicious.
      type: Boolean
    - contextPath: PhishLabsIOC.EIR.Email.URL.MaliciousDomain
      description: Whether the URL domain is malicious.
      type: Boolean
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.FileName
      description: Name of the attached file.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.MimeType
      description: Attachment MIME type.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.MD5
      description: MD5 hash of the attachment.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.SHA256
      description: SHA256 hash of the attachment.
      type: String
    - contextPath: PhishLabsIOC.EIR.Email.Attachment.Malicious
      description: Whether the file is malicious.
      type: Boolean
    - contextPath: Email.To
      description: The recipient of the email.
      type: String
    - contextPath: Email.From
      description: The sender of the email.
      type: String
    - contextPath: Email.Body/HTML
      description: The plain-text version of the email.
      type: String
    - contextPath: File.Name
      description: The full file name (including file extension).
      type: String
    - contextPath: File.SHA256
      description: The SHA256 hash of the file.
      type: Unknown
    - contextPath: File.MD5
      description: The MD5 hash of the file.
      type: String
    - contextPath: File.Malicious.Vendor
      description: The vendor that reported the file as malicious.
      type: String
    - contextPath: File.Malicious.Description
      description: A description explaining why the file was determined to be malicious.
      type: String
    - contextPath: URL.Data
      description: The URL.
      type: String
    - contextPath: URL.Malicious.Vendor
      description: The vendor reporting the URL as malicious.
      type: String
    - contextPath: URL.Malicious.Description
      description: A description of the malicious URL.
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: String
  dockerimage: demisto/python3:3.12.13.10116658
  isfetch: true
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- PhishlabsIOC_EIR-Test
fromversion: 5.0.0